Multi-Actor Espionage Campaign Weaponizes Balochistan Police Complaint Management Portal (PlugX, ShadowPad, Cobalt Strike, Remcos/TAG-179)
Multi-Actor Espionage Campaign Weaponizes Balochistan Police (TL-2026-1239), also tracked as One Target, Two Flags, is a high-severity advanced persistent threat campaign, first published 2026-07-11. It is attributed to TAG-179 (China, India) with high confidence, affects Balochistan Police Complaint Management System (CMS), maps to 38 MITRE ATT&CK techniques (T1005, T1008, T1016), and is covered by 9 detection rules and 43 indicators of compromise.
Key facts for TL-2026-1239
- Threat ID
- TL-2026-1239
- Also known as
- One Target, Two Flags, Balochistan Police CMS Compromise
- Severity
- HIGH
- Status
- ACTIVE
- Category
- APT
- First published
- 2026-07-11
- Last reviewed
- 2026-07-11
- Attribution
- TAG-179
- Attribution confidence
- HIGH
- Nation-state nexus
- China, India
- Motivation
- ESPIONAGE
- Target sectors
- government administration, police - law enforcement, defense, foreignaffairs, intelligence, academicresearch, telecoms, ngo, manufacturing, criticalinfrastructure
- Target regions
- pakistan, South Asia, Southeast Asia, 143 - Central Asia, East Asia, Middle East, Southeast Europe
- Detection rules
- 9
- Indicators of compromise
- 43
Malware and tooling in Multi-Actor Espionage Campaign Weaponizes Balochistan Police
Malware and tooling: AsyncRAT, PlugX, Remcos, ShadowPad, Cobalt Strike
SentinelLABS documented converging China-nexus (PlugX, ShadowPad, Cobalt Strike) and India-nexus (TAG-179/Remcos, overlapping Mysterious Elephant/APT-C-08/SideWinder/Confucius/Bitter TTPs) espionage clusters that separately compromised Pakistani law enforcement networks, including Balochistan Police, Khyber Pakhtunkhwa Police, Islamabad Police, and the Punjab Safe Cities Authority, between February 2024 and April 2026. The China-nexus actor weaponized the public-facing Balochistan Police Complaint Management System (cms.balochistanpolice.gov.pk) by uploading a custom implant (cms_plugin.exe) disguised as a portal update, compromising both police staff and citizen users.
How Multi-Actor Espionage Campaign Weaponizes Balochistan Police works
SentinelOne's SentinelLABS (researcher Aleksandar Milenkoski) published "One Target, Two Flags: Rival Espionage Actors Converge On Pakistani Law Enforcement," documenting a multi-year, multi-actor cyberespionage campaign against Pakistani police infrastructure. Two distinct, unrelated nation-state-nexus actor clusters independently compromised overlapping victim infrastructure: a suspected China-nexus cluster deploying PlugX (Feb 27-Sep 28, 2024), ShadowPad (Nov 5-Dec 1, 2024), and Cobalt Strike (Oct 12, 2024-Dec 2025); and a suspected India-nexus cluster tracked by Recorded Future as TAG-179, overlapping with Kaspersky's Mysterious Elephant (APT-K-47/APT-C-08) and related SideWinder/Confucius/Bitter TTP-sharing groups, deploying Remcos RAT (Jan 13-Apr 9, 2026) via a decoy document themed around Afghan Citizen Card (ACC) repatriation operations.
The most significant new development is the China-nexus actor's compromise of the Balochistan Police Complaint Management System (CMS), a public-facing web application at cms.balochistanpolice.gov.pk that is used both by police staff (restricted ps-[district] logins) and by ordinary citizens filing complaints. The attackers uploaded two variants of a custom implant named cms_plugin.exe to the portal's client-scripts directory, disguised as a routine portal update: a Rust-based stager and a .NET executable masquerading as the legitimate Chinese antivirus process 360Safe.exe (Qihoo 360). The .NET variant reflectively loads an embedded AsyncRAT client that calls back to 41.216.188.140. Compromised Chinese-language PDB paths (D:\codedome\case\six\Client\Client2\obj\Debug\Client2.pdb), the term "xinshi" (new variant), and Simplified Chinese log strings indicate a Chinese-speaking developer.
Beyond the CMS, the China-nexus actors compromised Balochistan Police web servers hosting the First Information Report (FIR) system, the Human Resource Management Information System (HRMIS), the Anti-Vehicle Lifting System (AVLS), HotelEye (hotel/tenant tracking with NADRA national-ID integration), the Criminal Record Management System (CRMS, biometric records), the Tenant Registration System (TRS), two network appliances, and a Fortinet FortiMail email gateway appliance — all part of an EU-supported "Smart Police Station" digitalization initiative that was turned into an intelligence-collection vector.
SentinelLABS assesses with high confidence that the China-nexus activity is motivated by Beijing's concern for the safety of Chinese nationals connected to the China-Pakistan Economic Corridor (CPEC), following deadly attacks on Chinese personnel including the October 2024 Karachi airport bombing and a March 2024 suicide bombing, both attributed to the Balochistan Liberation Army (BLA); China sought independent insight into Pakistan's internal security posture ahead of a January 2026 China-Pakistan counterterrorism coordination agreement. The India-nexus/TAG-179 activity is assessed as driven by the long-running India-Pakistan security rivalry and interest in Balochistan's insurgency dynamics and cross-border militancy dynamics. Victimology for the broader PlugX/ShadowPad/Cobalt Strike and TAG-179/Mysterious Elephant clusters spans government, foreign affairs, defense, intelligence, academic/research, telecommunications, NGO, and manufacturing targets across South Asia (India, Bangladesh, Nepal, Sri Lanka), Southeast Asia (Vietnam, Thailand, Philippines), Central Asia (Kazakhstan, Tajikistan), East Asia (China, Taiwan — including Tibetan Buddhist organizations), the Middle East/Arabian Peninsula (Saudi Arabia, UAE, Iran), and Southeast Europe.
No CVEs were disclosed in the source reporting; initial access to the CMS and internal networks appears to rely on compromised credentials, direct web-application upload access, and trust in a public-facing government portal rather than a specific software vulnerability.
MITRE ATT&CK techniques used in TL-2026-1239
Collection
T1005 Data from Local System; T1056 Input Capture; T1113 Screen Capture; T1114 Email Collection; T1123 Audio Capture
Command and Control
T1008 Fallback Channels; T1071.001 Web Protocols; T1105 Ingress Tool Transfer; T1573 Encrypted Channel
Discovery
T1016 System Network Configuration Discovery; T1087 Account Discovery; T1518 Software Discovery
Exfiltration
T1020 Automated Exfiltration; T1041 Exfiltration Over C2 Channel
Lateral Movement
Defense Evasion
T1027 Obfuscated Files or Information; T1036 Masquerading; T1036.005 Match Legitimate Resource Name or Location; T1140 Deobfuscate/Decode Files or Information; T1620 Reflective Code Loading
Credential Access
T1056.001 Keylogging; T1110 Brute Force; T1187 Forced Authentication
Execution
T1059 Command and Scripting Interpreter; T1106 Native API; T1204.002 Malicious File
Initial Access
T1078 Valid Accounts; T1189 Drive-by Compromise; T1199 Trusted Relationship; T1566.001 Spearphishing Attachment
Privilege Escalation
Persistence
T1505.003 Web Shell; T1547 Boot or Logon Autostart Execution; T1554 Compromise Host Software Binary
Impact
Resource Development
T1583.004 Server; T1587.001 Malware
Reconnaissance
T1591 Gather Victim Org Information
defense-impairment
Affected products and versions in Multi-Actor Espionage Campaign Weaponizes Balochistan Police
- Balochistan Police — Complaint Management System (CMS)
Vulnerable versions: cms.balochistanpolice.gov.pk (all versions prior to remediation) - Balochistan Police — First Information Report (FIR) System
Vulnerable versions: deployed instance, 2024-2026 - Balochistan Police — Human Resource Management Information System (HRMIS)
Vulnerable versions: deployed instance, 2024-2026 - Balochistan Police — Anti-Vehicle Lifting System (AVLS)
Vulnerable versions: deployed instance, 2024-2026 - Balochistan Police — HotelEye (hotel/tenant tracking, NADRA-integrated)
Vulnerable versions: deployed instance, 2024-2026 - Balochistan Police — Criminal Record Management System (CRMS)
Vulnerable versions: deployed instance, 2024-2026 - Balochistan Police — Tenant Registration System (TRS)
Vulnerable versions: deployed instance, 2024-2026 - Fortinet — FortiMail
Vulnerable versions: appliance deployed as Balochistan Police primary email gateway
Remediation for Multi-Actor Espionage Campaign Weaponizes Balochistan Police
Immediate actions
- Block identified C2 IPs (172.111.233.36/96/12/105/26, 172.94.9.49/43/19, 45.74.6.17, 45.125.32.218, 142.171.183.8, 193.42.25.65, 41.216.188.140, 89.31.121.220) at network perimeter
- Remove cms_plugin.exe and 360Safe.exe-masquerading binaries from all Balochistan Police CMS servers and endpoints
- Force credential resets for all ps-[district] police staff CMS accounts and FortiMail administrative accounts
- Isolate and forensically image the two compromised network appliances and the FortiMail gateway
Workarounds
- Digitally sign and verify all client-side downloads served from government portals before user execution
- Disable direct file upload/execution capability on public complaint-management web servers pending network segmentation
Longer-term hardening
- Segment citizen-facing web applications (CMS, complaint portals) from internal law-enforcement networks and databases
- Implement mandatory multi-factor authentication for all law-enforcement portal and email-gateway logins
- Deploy application-layer intrusion detection and file-integrity monitoring on all public-facing government web servers
- Establish a secure software update/signing process for portal client-side executables to prevent trojanized 'update' uploads
- Conduct dark-web credential exposure monitoring for police-domain accounts
Weaknesses (CWE) in Multi-Actor Espionage Campaign Weaponizes Balochistan Police
CWE-506, CWE-829, CWE-345
Timeline of Multi-Actor Espionage Campaign Weaponizes Balochistan Police
- China-nexus actor begins PlugX backdoor deployment against Pakistani law enforcement networks.
- March 2024 suicide bombing targeting Chinese nationals in Pakistan, attributed to the Balochistan Liberation Army, heightening Chinese security interest in the region.
- Compromise of Balochistan Police infrastructure, including the Complaint Management System, begins (per SentinelLABS observed range June 2024-April 2026).
- Observed PlugX C2 activity against Pakistani law enforcement ends.
- Chinese Ambassador issues statement on Pakistan security situation following attacks on Chinese nationals.
- China-nexus actor begins Cobalt Strike operations against multiple Pakistani law-enforcement-linked targets.
- Karachi airport attack by the Balochistan Liberation Army targeting Chinese nationals, reinforcing Beijing's motivation for independent security intelligence collection in Pakistan.
- China-nexus actor deploys ShadowPad backdoor against Pakistani law enforcement infrastructure.
- Custom cms_plugin.exe implants (Rust stager and .NET/360Safe.exe-masquerading variant) uploaded to the Balochistan Police CMS client-scripts directory, disguised as a routine portal update.
- Observed ShadowPad C2 activity ends.
- First phase of observed Cobalt Strike C2 activity against Balochistan Police-linked infrastructure ends (broader Cobalt Strike activity continues through December 2025).
- TAG-179 (India-nexus) begins Remcos RAT campaign against Pakistani law enforcement, using an Afghan Citizen Card repatriation-themed decoy document.
- China and Pakistan reach a counterterrorism coordination agreement, aligning with China's continued interest in independent security intelligence on Pakistan.
- Observed TAG-179 Remcos C2 activity against Pakistani law enforcement ends.
- SentinelOne SentinelLABS publishes "One Target, Two Flags," documenting the converging China-nexus and India-nexus campaigns against Pakistani law enforcement, including the Balochistan Police CMS weaponization.
- The Hacker News and other outlets publish coverage of the SentinelLABS findings, amplifying public disclosure of the CMS portal weaponization.
Sources cited for Multi-Actor Espionage Campaign Weaponizes Balochistan Police
- One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement
- Hackers Weaponize Balochistan Police Portal in Espionage Campaign
- China, India ran separate spying campaigns against same Pakistani police force
- SentinelLABS Pakistan Police Cyberespionage Report Findings
- Chinese and Indian State-Linked Hackers Target Pakistani Police Networks in Multi-Year Cyber Espionage Campaign
- SentinelOne Report Alleges China-India Linked Hackers Targeted Pakistan's Police Networks
- China and India-Linked Hackers Target Pakistan Police Networks, SentinelLABS Report Reveals
- APT-K-47 "Mysterious Elephant", a new APT organization in South Asia
- Mysterious Elephant APT: TTPs and tools
- Mysterious Elephant: The Stealthy Hacker Group Targeting Asia's Diplomatic Circles
- South Asia's Cyber Arms Race Intensifies as New APTs Emerge
Threats related to Multi-Actor Espionage Campaign Weaponizes Balochistan Police
Detection coverage for TL-2026-1239
As of 2026-07-11, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1239 across Splunk SPL, Microsoft KQL and Sigma, covering 43 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.
Community OSINT corroboration for TL-2026-1239
1 of this threat's indicators have also been reported by the open-source security community, which observed at least one of them before this report was published. Community sightings are unverified and are kept separate from Threadlinqs' curated indicators. Indicator values, reporters and campaign linkage are available to authenticated Red-tier users.